[Bug 296598] inbound ipsec packets get tracked via outer ip header when the tunnel runs over if_wg

[email protected] Fri, 31 Jul 2026 08:46:48 +0000
Newsgroups gmane.os.freebsd.devel.net
Message-ID <[email protected]/bugzilla/>
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D296598

--- Comment #14 from Lars Kr=C3=A4mer <[email protected]> ---
(In reply to Andrey V. Elsukov from comment #13)
It's a bit of a question of who's supposed to be responsible for handling t=
hese
edgecases. As of 15.x, it seems like pf is also doing a m_pullup before try=
ing
to read from the mbuf. That would lead me to believe this isn't ipsec's
responsibility.
The patch was more of a proof of concept, to show that this is actually wha=
t is
happening, not really meant to be pulled as is.
The only open question in my mind is if this justifies a patch for 14.x.
While the way I encountered it is a little esoteric, there's clearly a bug
here.

--=20
You are receiving this mail because:
You are the assignee for the bug.=